If the virus Hybris has no Plugin features for sending text messages, it sends a message without subject and sender.

Technical Details

When first activated, W95/Hybris.PI.003 tries to infect WSOCK32.DLL in %WinDIR%/%SystemDIR%.
It tries to directly infect WSOCK32.DLL. If it can not be done, because the file is already in use, the worm makes an infected copy of WSOCK32.DLL. The copy has no extension and its name has 8 random characters.
The worm enters a line in WININIT.INI, so that when the computer starts-up again, the copy will replace the original WSOCK32.DLL file.
The modified file surveys all Internet activities and tries to write a copy of the worm in an .EXE or .SCR file, to send it to email addresses.
This Internet worm downloads encoded updates from Internet websites: